You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE需迁移API:gkebackup/agent调用废弃的PodSecurityPolicy API

GKE备份Agent触发废弃PSP API调用问题处理

问题说明

使用GKE Backup的ProtectedApplication(gkebackup.gke.io/v1alpha2版本)备份集群ConfigMap时,集群告警显示gkebackup/agent调用了已废弃的policy/v1beta1/podsecuritypolicies API。当前集群中仍存在该版本的PodSecurityPolicy(例如gce.gke-metrics-agent),该API自K8s 1.21版本起废弃,1.25版本后完全不可用。

原因解析

GKE Backup Agent在执行备份任务时,会扫描集群内关联的资源权限与配置,即便仅备份ConfigMap,Agent仍可能尝试访问集群中存在的PodSecurityPolicy资源。由于集群遗留了policy/v1beta1版本的PSP,触发了废弃API的调用告警。

解决步骤

  • 升级Backup Agent版本:更新GKE Backup Agent至适配K8s新版本API的版本,新版本会使用非废弃的API接口访问PSP资源
  • 迁移/清理废弃PSP:将集群中policy/v1beta1版本的PodSecurityPolicy迁移至policy/v1版本(集群版本支持的前提下),或直接删除不再使用的PSP资源
  • 缩小备份范围:调整ProtectedApplication的资源选择器,仅包含需要备份的ConfigMap,减少Agent的资源扫描范围,避免不必要的API调用

相关命令输出

执行命令:kubectl get --raw /apis/policy/v1beta1/podsecuritypolicies | jq

Warning: policy/v1beta1 PodSecurityPolicy is deprecated in v1.21+, unavailable in v1.25+
{
  "kind": "PodSecurityPolicyList",
  "apiVersion": "policy/v1beta1",
  "metadata": {
    "resourceVersion": "559423101"
  },
  "items": [
    {
      "metadata": {
        "name": "gce.gke-metrics-agent",
        "uid": "05930fb8-da4e-4036-88ef-213f6e8fd3c6",
        "resourceVersion": "553418154",
        "creationTimestamp": "2021-03-17T14:17:52Z",
        ...
  ]
}

执行命令:kubectl describe protectedapplication backup-app

Name:         backup-app
Namespace:    default
Labels:       <none>
Annotations:  <none>
API Version:  gkebackup.gke.io/v1alpha2
Kind:         ProtectedApplication
Metadata:
  Creation Timestamp:  2023-03-24T07:48:27Z
  ...

内容的提问来源于stack exchange,提问作者Daniel Rusu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 03:35:14